
Axios npm Hit by Trojan Supply Chain Attack
Hackers stole an npm token from an axios maintainer to publish two malicious versions with a cross-platform RAT. The packages targeted macOS, Windows, and Linux, live for three hours and detected infecting 135 systems. This is the third major npm compromise in seven months, bypassing recommended defenses via CLI publish.






